Skip to content
RefinoGet early access

How to transfer a domain without breaking your website

Moving a domain between registrars is routine and usually uneventful. The sites that go dark during a transfer go dark because someone changed DNS at the same time. This guide separates the three things people mean by “transfer” and walks through the one you probably need.

Published September 11, 2026 · About a 10 minute read

What you’ll learn

  • Registrar transfer, DNS change and host change are three different things
  • What a transfer lock and an authorization code are
  • How long a transfer takes and what the approval emails mean
  • Why you export your DNS records before you start
  • How to verify the site and email afterwards

Three different things people call “transferring a domain”

Before doing anything, be clear which of these you mean, because they are separate operations with separate risks:

  1. A registrar transfer moves the domain from one registrar to another, or from someone else’s account to yours. It changes who you pay and where the controls are. It does not, by itself, change where the website is.
  2. A DNS change changes where the domain points: which server answers for the website, which service handles email. It happens in the DNS panel and doesn’t involve the registrar changing.
  3. Changing hosting providers moves the website itself to a different company. It ends with a DNS change so the domain points at the new host. The registrar isn’t involved.

This guide is about the first one, moving the domain to a registrar account you control, and about keeping the other two out of it. Most transfers that break a website do so because someone did all three at once.

Transferring a domain does not have to change where the site points

A registrar transfer moves the registration. The DNS records that point your domain at your website and email can stay exactly as they are, provided the nameservers stay the same. Your nameservers are listed at the registrar and normally carry over unchanged. If they belong to a third party such as Cloudflare, nothing about DNS changes at all during a transfer.

The one case that needs care is when the domain uses the old registrar’s own nameservers. Once the domain leaves, the old registrar may stop answering for it, and the records it held stop working. In that case you need the same records set up at the new registrar before the transfer completes. Some registrars import or scan for your existing records during the transfer; none guarantees to find all of them. The section on nameservers below covers how to do this safely.

Before you transfer

  • I can log in to the current registrar account, or the person who can is ready to help.
  • The domain was registered, and last transferred, more than 60 days ago.
  • I haven’t changed the registrant name, organization or email on the domain in the last 60 days, or I opted out of the lock when I did.
  • The contact email on the domain is one I can read today; the approval emails go there.
  • The domain isn’t expired or about to expire. If it expires during the transfer, things get complicated; renew first.
  • I have exported or screenshotted every DNS record: every A, AAAA, CNAME, MX, TXT and SRV record, with its name, value and TTL.
  • I know which nameservers the domain uses, and I have written them down.
  • If DNSSEC is turned on, I’ve checked whether the new registrar wants it turned off before the transfer starts.
  • I have an account at the new registrar, with 2FA on and my payment method added.
  • If the new registrar requires its own nameservers, the DNS records are already set up there and I’ve checked they match.

The DNS export is the item people skip. It takes five minutes, and if anything goes wrong it turns a day of guesswork into ten minutes of typing.

The transfer lock

Most registrars keep a “transfer lock” on your domain by default. It’s a status on the registration, sometimes shown as “locked” or “clientTransferProhibited”, that blocks transfer requests. It’s there to stop your domain being moved without your knowledge. To transfer, you turn it off in the current registrar’s account, usually with a single switch, and turn it back on at the new registrar afterwards.

Separately, there are waiting periods set by the rules that govern registrars. At the time of writing, under ICANN’s Transfer Policy:

  • A registrar may refuse a transfer within 60 days of the domain being registered, or within 60 days of a previous transfer. Most registrars apply this, so treat it as a rule.
  • Changing the registrant’s name, organization or email address puts the domain under a mandatory 60-day lock. Some registrars let you opt out of that lock at the moment you make the change; they aren’t required to offer it.

So if you’ve just bought the domain, or just updated the contact details, the transfer may have to wait. Plan for it rather than fighting it.

The authorization code

To prove you’re allowed to move the domain, the current registrar gives you an authorization code, also called an auth code, EPP code or transfer code. It’s a unique password for this one domain. You get it from the current registrar’s account, usually next to the transfer lock setting, and enter it at the new registrar to start the transfer.

The current registrar is required to give you the code within five calendar days of your asking, and can’t withhold it because of a billing dispute. Treat the code as a secret: anyone who has it and knows your domain can start a transfer.

Approval emails and how long it takes

Once you enter the code and pay at the new registrar, the transfer request goes to the registry, which tells the current registrar. What happens next:

  • The current registrar has five calendar days to approve or refuse. If it does nothing, the transfer goes through automatically at the end of that period.
  • The current registrar sends an email to the domain’s contact address confirming the request. Many registrars include an “approve now” link, which finishes the transfer in minutes rather than days. Some also offer that button inside the account.
  • You may get an email from the new registrar as well. Read it, but don’t act on any message you weren’t expecting; the transfer only needs the code and, optionally, your approval at the old registrar.

Registrars generally quote five to seven days end to end, with some allowing for up to ten or fifteen. For most of the common domain endings, a successful transfer also adds a year to the registration, which is what the transfer fee pays for. The exception is a domain renewed within the last 45 days after expiring, which may not get the extra year.

The dangerous part: changing nameservers

Nameservers tell the internet which DNS service holds your domain’s records. Changing them swaps out every record at once. If the new nameservers don’t already have the same records the old ones had, the website, the email, or both stop working the moment the change takes effect.

A registrar transfer doesn’t change nameservers on its own. But several situations push you into changing them around the same time: the old registrar’s nameservers stop serving once the domain leaves; the new registrar requires its own nameservers, as Cloudflare does; or a helpful “use our DNS” checkbox is ticked by default. The safe sequence is always the same:

  1. Set up every record from your export at the new DNS provider first. Compare the two lists line by line.
  2. Only then change the nameservers to point at the new provider.
  3. Leave the old records in place until you’ve verified the site and email on the new ones.

The mistake to avoid is changing nameservers with an empty or half-imported set of records on the other side. That’s the usual cause of “we transferred the domain and the website disappeared”, and it’s a DNS problem, not a transfer problem.

What “DNS propagation” actually means

DNS propagation is the period after a DNS change during which some people still see the old answer and some see the new one. It isn’t the change spreading across the internet; it’s caches expiring. Every DNS record has a time-to-live, or TTL, which tells other servers how long they may remember the answer before asking again. Until each cache’s copy expires, it keeps handing out the old value.

So a record with a TTL of five minutes updates for most people within minutes, while a record with a TTL of a day can take a day. Nameserver changes are slower still: the registrar has to pass them up to the registry, and Cloudflare’s own guidance is to allow up to 24 hours. If you’re planning a change, lowering the TTL on the affected records a day in advance shortens the overlap.

After you transfer

  • The domain shows in the new registrar account, with my name as the registrant and an expiry date about a year later than before.
  • The transfer lock is back on at the new registrar.
  • Auto-renew is on, with my payment method.
  • Two-factor authentication is on for the new account, and the recovery codes are saved.
  • Domain privacy is on.
  • The nameservers are the ones I wrote down, or the new ones I set up deliberately.
  • Every record from my export exists at the DNS provider now in use.
  • The website loads at the domain, with and without “www”, and over https.
  • Email at the domain works: I’ve sent a message to it and received a reply from it.
  • Anything else the domain pointed at, such as a subdomain for an app or a verification record for a service, still works.
  • The old registrar account is closed or the payment method is removed, once nothing else lives there.

On checking email: outgoing mail relies on TXT records (SPF, DKIM and DMARC) as well as the MX records for incoming mail. If those didn’t survive, your messages may be delivered to spam rather than bouncing, which is easy to miss. Send a test to an address at a different provider and check where it lands.

If you’re transferring the domain as part of leaving a builder, the exit guide puts this step alongside the others.

The rules are changing

Sources

The rules and product behaviour described above were checked against these pages when the guide was last updated. If something here has changed, these are the places to look.

Keep going

Or go back to the overview of what owning your site means, which ties all of these together.

  • How to register a domain you actually own

    What a domain and a registrar are, why the registrar account should be yours, and the settings that keep the domain yours: recovery email, two-factor authentication, auto-renew and privacy. With a checklist.

    About a 8 minute read

  • GitHub is not your web host

    GitHub stores the code for your website. A host such as Cloudflare, Vercel or Netlify serves it to visitors. DNS connects your domain to the host. Why these are separate, and who should control each one.

    About a 7 minute read

Early access

Refino is not open to everyone yet.

We are working with a small number of site owners first. If you built a site with AI and want to be able to change its words yourself, tell us about it. We read every message and reply ourselves.